AshortandeasyboilerplateshowcasingJWTauthwithNodejs,theServerlessframework,MongoDBandAWSLambda.
TheauthfolderhasaVerifyToken.jsfilewhichisthebaseoftheauthorizerfunction.TheVerifyToken.authmethodisaddedtotheauthorizerfieldintheserverless.ymlforAPIGatewayroutesyouwishtokeepprivate.Seethemefunction.AuthHandler.meusesevent.requestContext.authorizer.principalIdtoaccesstheuserIdoftheuseraccessingtheresourceiftheJWTisvalid.Otherwisereturns'Unauthorized'.Note:Theconceptofmiddlewarescanbeappliedtothisforunderstandingiteasily.
评论